Global ingress
Exact hostnames, managed certificates and global edge protection form the launch route.
The launch path uses Cloudflare for SaaS. Envoy and Coraza preserve first-party policy, telemetry and an incremental path toward Native Edge.
The control plane compiles logical intent. Provider adapters translate it without changing cases, safety contracts, evidence or customer workflows.
Current state is shown only after a fresh, schema-validated snapshot is loaded.
Open status evidenceThese cards describe product scope. Current delivery stage, runtime health, scope and freshness are reported separately from the validated public snapshot above.
Exact hostnames, managed certificates and global edge protection form the launch route.
Envoy and Coraza provide service-specific inspection and future provider portability.
A modular Go application, durable jobs and RLS keep the control plane understandable and testable.
Sigma and STIX content, customer SIEM/DFIR tools and bounded scanners contribute evidence without becoming request-path dependencies.
The visitor path remains short. Configuration, verification and rollback stay visible to the operator at every stage.
The edge enforces the last valid signed policy.
The control plane records cases, workflows and provider reconciliation.
Continuity storage must survive both edge and origin failure.
AegiFlow does not turn missing evidence into a reassuring zero. Every state links to its source, freshness and next action.
How this capability behaves in production — grounded in the platform's documented, current operation.
The path a visitor's request takes is short and local: global ingress, the AegiFlow edge, your origin. Everything else — correlation, threat feeds, dashboards, reports — runs asynchronously in the control plane and can degrade without touching traffic.
Protected origins can stay entirely private, reachable only over mutual TLS from the AegiFlow edge, while the platform's own connections are outbound-only tunnels. There is no inbound port waiting to be found, and the provider-neutral edge preserves an exit path from any single vendor.
Ownership, certificate, origin health and rollback must pass before traffic protection changes.